You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

升级passport-saml至@node-saml/passport-saml后认证失败求助

问题:升级@node-saml/passport-saml后认证功能失效

原passport-saml包已废弃,我将其升级为@node-saml/passport-saml,参照官方示例编写代码时,发现无法用原方式导入:

const SamlStrategy = require('passport-saml').Strategy;

于是改成以下导入方式:

const SamlStrategy = require('@node-saml/passport-saml').Strategy;

代码未抛出模块未找到错误,但更换包后认证功能完全失效,login/callback路由仅显示"error",即便添加了错误日志也无法查看具体错误信息。

解决方案:调整SAML策略签名配置项

需根据IdP提供商的要求,在策略配置中添加wantAssertionsSigned和wantAuthnResponseSigned两个选项:

wantAssertionsSigned:若设为true,会在元数据中添加WantAssertionsSigned="true",指定IdP必须始终对断言签名,默认开启。注意:即使两者都关闭,响应或断言中也必须有一个被签名。
wantAuthnResponseSigned:若设为true,要求所有传入的认证响应消息在顶层签名,而非仅在断言层面,默认开启。注意:即使两者都关闭,响应或断言中也必须有一个被签名。

配置示例:

samlStrategy = new SamlStrategy({
  issuer: process.env.saml_issuer,
  protocol: 'https://',
  path: '/login/callback',
  entryPoint: process.env.saml_entrypoint,
  cert: process.env.cert,
  wantAssertionsSigned: false,
  wantAuthnResponseSigned: false
}, function (profile, done) {
  return done(null, profile);
});

内容的提问来源于stack exchange,提问作者Arunprasath

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 01:31:08